Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2020-14029 An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the applica… Ozeki Ng Sms Gateway after 4.17.6 Fix from $1,9502020-09-18 HIGH 7.5 CVE-2020-25750 An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the c… Dotplant2 2020-09-14+ Fix from $1,9502020-09-18 CRITICAL 9.8 CVE-2020-25215 yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document. Yed 3.20.1+ Fix from $2,3002020-09-17 HIGH 7.5 CVE-2020-11991EPSS 72% When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to acc… Cocoon after 2.1.12 Fix from $1,9502020-09-11 CRITICAL 9.8 CVE-2020-25257 An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and … Onbase after 20.3.10.1000 Fix from $2,3002020-09-11 HIGH 7.5 CVE-2020-17408EPSS 74% This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is n… Expresscluster X Patch available Fix from $1,9502020-09-10 CRITICAL 9.8 CVE-2020-24379 WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. Ubuntu Linux after 2.0.7 Fix from $2,3002020-09-09 HIGH 7.1 CVE-2020-2245 Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Valgrind after 0.28 Fix from $1,9502020-09-01 MEDIUM 6.5 CVE-2020-2247 Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Klocwork Analysis after 2020.2.1 Fix from $1,6002020-09-01 CRITICAL 9.8 CVE-2020-25020 MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. Mpxj after 17.12 Fix from $2,3002020-08-29 HIGH 8.3 CVE-2020-17376 An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a so… Nova 19.3.1 / 20.3.1+ Fix from $1,9502020-08-26 MEDIUM 6.5 CVE-2020-24656 Maltego before 4.2.12 allows XXE attacks. Maltego 4.2.12+ Fix from $1,6002020-08-26 MEDIUM 6.5 CVE-2020-24591 The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager … Api Manager after 5.6.0 Fix from $1,6002020-08-21 CRITICAL 9.1 CVE-2020-24589EPSS 26% The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. Api Manager after 3.1.0 Fix from $2,3002020-08-21 CRITICAL 9.1 CVE-2020-24052 Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbi… Exvf5c 2 Firmware No fix yet Fix from $2,3002020-08-21 HIGH 8.2 CVE-2020-4481 IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML … Urbancode Deploy Mitigation only Fix from $1,9502020-08-05 CRITICAL 9.1 CVE-2020-4377 IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could ex… Cognos Analytics Mitigation only Fix from $2,3002020-08-03 HIGH 8.2 CVE-2020-4463EPSS 32% IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote att… Maximo Asset Management Patch available Fix from $1,9502020-07-29 HIGH 7.5 CVE-2020-15419EPSS 60% This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati… One Firmware 9.5.4.4587 / 10.0.0.750+ Fix from $1,9502020-07-28 HIGH 7.5 CVE-2020-15418EPSS 9% This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati… One Firmware 9.5.4.4587 / 10.0.0.750+ Fix from $1,9502020-07-28 HIGH 7.3 CVE-2020-3405 A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to informa… Sd Wan Firmware after 19.2.2 Fix from $1,9502020-07-16 HIGH 8.2 CVE-2020-4462 IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnera… Sterling External Authentication Server Mitigation only Fix from $1,9502020-07-16 CRITICAL 9.8 CVE-2020-12684 XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a re… I Net Clear Reports Mitigation only Fix from $2,3002020-07-15 HIGH 7.1 CVE-2019-17637 In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to … Debian Linux after 3.18 Fix from $1,9502020-07-15 MEDIUM 5.5 CVE-2020-4510 IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit … Qradar Security Information And Event Manager after 7.3.2 Fix from $1,6002020-07-14 HIGH 7.5 CVE-2020-5602 Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, … Cpu Module Logging Configuration Tool after 1.590q Fix from $1,9502020-06-30 HIGH 7.5 CVE-2020-14940 An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gp… Tuxguitar Patch available Fix from $1,9502020-06-23 HIGH 8.2 CVE-2020-14204 In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local files or forge server-side HTT… Webfocus Business Intelligence Mitigation only Fix from $1,9502020-06-22 MEDIUM 6.5 CVE-2020-8541 OX App Suite through 7.10.3 allows XXE attacks. Open Xchange Appsuite No fix yet Fix from $1,6002020-06-16 MEDIUM 6.7 CVE-2020-13883 In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE durin… Api Manager after 5.9.0 Fix from $1,6002020-06-06